Skip to content
Suncly Data

Know what enters a test, and what leaves it.

How Suncly handles data, verified against the code. The command-line tool runs where you run it and sends nothing to Suncly in this version. Suncly Data is how data is handled; it is not a dataset, and nothing you test trains anything.

Inventory

WhatWhere it is storedWho can read itHow to delete it
The Agent Card you point Suncly atThe evidence store (files under ~/.suncly/store, or your Postgres)Whoever can read that storeRemove the files or drop the database
The test plan and its approval (contract, test cases, approved_by)The evidence storeWhoever can read that storeRemove the files or drop the database
Redacted transcripts of every run~/.suncly/transcripts on the machine that ran itWhoever can read that folderRemove the files
Your agent credentialOnly the Runner process, from one environment variable; never writtenNobody; it is redacted from every transcriptUnset the variable
The deployment signing key~/.suncly/keysWhoever can read that folderDelete the key; earlier reports still verify with the public key in result.json
Report folders./suncly-reports/<attestation-id>/Whoever you give them toDelete the folder

Anatomy of a report folder

FileContents
report.htmlThe report for a reviewer. Self-contained; opens offline.
report.mdThe same content as Markdown.
result.jsonThe evidence bundle: attestation, runs, decisions, card version, contract, results, the signed payload and the public key.
transcripts/<run-id>.jsonOne redacted transcript per run, with its Layer 1 checks.

Deletion, truthfully

The evidence store is append-only by design: run and decision records are never updated or deleted by the software. You delete by removing files or dropping the database. For a hosted service, append-only evidence and erasure requests will need a documented answer; that question is open and recorded in HANDOFF.md.

What changes when the hosted API arrives

  • Evidence for hosted evaluations would be stored by Suncly, under a data processing agreement, with a published sub-processor list.
  • Accounts and API keys would exist; the Privacy Policy's hosted sections switch on then.
  • The Runner is designed to run inside your network later, so credentials can stay there.

Verified against src/suncly on 2026-10-05. The security page covers credentials, redaction and the non-negotiable rules: /security. The Privacy Policy covers this website: /privacy.

A closed box with one narrow slit. A single blade of light leaves it toward the lower left.